CVE-2022-22326

LOW

IBM Datapower Gateway - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6560048
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6608598
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/218856

Scores

CVSS v3 3.3
EPSS 0.0005
EPSS Percentile 17.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-863
Status published
Products (5)
ibm/datapower_gateway 10.0.1.0 - 10.0.1.6
ibm/mq_appliance_m2001_firmware < 9.2.0.5
ibm/mq_appliance_m2001_firmware < 9.2.5
ibm/mq_appliance_m2002_firmware < 9.2.0.5
ibm/mq_appliance_m2002_firmware < 9.2.5
Published Aug 01, 2022
Tracked Since Feb 18, 2026